stamparm / maltrail

Malicious traffic detection system
MIT License
5.94k stars 1.02k forks source link

Remove improper aliases for teamspy #19240

Closed HSZemi closed 5 months ago

HSZemi commented 5 months ago

Judging by the commit history, it seems like the aliases "phichichi" and "socks5systemz" were taken from this Tweet: https://twitter.com/g0njxa/status/1701212547305607283 image

However, the tweet seems to instead indicate that the given IP addresses are Socks5 Systemz systems that are being used by TeamSpy. It does not suggest that Socks5 Systemz is the same as TeamSpy.

Also, Pichichi/phichichi appears to be just the title on the displayed website, not the name of a malware family.

See also:

MikhailKasimov commented 5 months ago

This simplified the search, when you can't remind what is what. "Thanks" for that...